SD-14.7 — Internal Control & Assurance
Business Domain: BD-14 Enterprise Risk, Control & Assurance (Cross-cutting — corporate) · Applies: BOTH
Purpose
Designs and monitors the firm’s internal-control framework, and gathers the management assurance that the controls work. SD-14.7 owns the control framework — the structured set of controls across the firm’s processes — maintains it to a recognised standard, runs the control attestations, and reviews the control-assurance reports the firm’s service providers supply. It is management’s own assurance that the firm is in control. It is not independent third-line assurance — that is SD-14.8 Internal Audit, which independently tests whether SD-14.7’s framework is effective — and it is not the commercial management of the service providers, which is SD-17.8; SD-14.7 reviews a provider’s control-assurance report, SD-17.8 manages the provider relationship.
It owns the trend-across-events cadence of control improvement, which is distinct from the per-event investigation the first line runs. The cadence boundary is the three-lines cut: when an operational break or control failure occurs, the first line investigates that event to its root cause and resolves it — a reconciliation break is investigated and closed by SD-12.10 Reconciliation, a compliance breach by SD-10.8. SD-14.7 sits at the second/third line: it does not re-investigate each event, but analyses the population of events over time to find the systemic control weaknesses a single investigation cannot see, and feeds the resulting framework changes back into the controls. Per-break root cause is the first line’s, at break cadence; root-cause trend analysis and control improvement is SD-14.7’s, at the continuous-improvement cadence.
Service Operations
- Design the control framework — define and maintain the firm’s internal-control framework across its processes, to a recognised standard.
- Monitor and test controls — monitor that the controls are operating, and run first/second-line control testing.
- Run control attestation — operate the control self-certification and attestation process across the firm.
- Review service-provider assurance — review the SOC 1 / ISAE 3402 and SOC 2 control-assurance reports the firm’s administrators, custodians and other providers supply.
- Run control-failure root-cause-trend analysis and control-improvement feedback — analyse the trend across control failures and operational breaks — reconciliation breaks, compliance breaches, oversight exceptions, loss events — to find the systemic causes a single per-event investigation does not surface, and feed the resulting control-design improvements back into the framework. This is the continuous-improvement cadence: it consumes the per-event evidence the first line produces (the reconciliation-break records and their per-break root cause from SD-12.10, the compliance-breach records from SD-10.8, the oversight exceptions from SD-12.16) and turns the population of events into a control-design verdict — which control failed, how often, where the framework needs strengthening.
- Report control status — report the state of the control environment to management and the audit committee.
Inputs and outputs
- Inputs: the firm’s processes and risks; the control evidence from across the model (for example the reconciliation-control evidence from SD-12.10); the per-event records the trend analysis runs over — the reconciliation breaks and their per-break root cause (SD-12.10), the compliance-breach records (SD-10.8), the oversight exceptions (SD-12.16); the service-providers’ assurance reports.
- Outputs: the control framework, the attestation record, the control-status report and the control-improvement actions the root-cause-trend analysis produces — consumed by SD-14.8 Internal Audit, the audit committee and the governing bodies, and fed back to the first-line operating Service Domains whose controls are being strengthened.
Entities
- Consumes: the control and process records across the model; the SD-12.10 control evidence from across the model; E-36 Oversight Exception (from SD-12.16 — the continuous-control evidence over delegated processing the management-assurance picture consumes).
- Owns: the firm’s control framework and attestation record — a process artefact.
Standards
- The COSO Internal Control–Integrated Framework — including its Monitoring Activities component, the basis of the control-improvement feedback loop: deficiencies are evaluated and communicated to the parties responsible for taking corrective action, the continuous-improvement cadence the root-cause-trend Service Operation runs.
- SOC 1 / ISAE 3402 and SOC 2 — the service-auditor reports SD-14.7 reviews.
- The Three Lines Model — internal control as first/second-line management assurance; the model’s separation of the first line’s per-event operation from the second/third line’s framework ownership is the basis of the root-cause-trend cadence cut against SD-12.10.
- The BIAN Case Root Cause Analysis Service Domain (in BIAN’s Servicing area) — the reference-model precedent for treating root-cause analysis as a discipline distinct from per-case investigation, an analysis run across cases to drive systemic improvement.
Open extensions
- A Control / Control-Finding entity.
- The control-attestation sub-model.
- The Service-Operation-level input/output contracts.